Privacy
Your workspace.
Your choices.
This policy covers the Cavreno app, its notification service, and cavreno.app. Cavreno is published by Ali Ramlaoui. For privacy questions, write to [email protected].
Last updated: 11 September 2026
Connections and local storage
Cavreno connects to the SSH host you select. Terminal commands, remote files, and coding-agent interactions are exchanged with that host over SSH. Your host and any services you use from it have their own access and retention practices.
Saved SSH passwords, imported private keys, and saved CLI logins are stored in the device Keychain. Host details, workspace preferences, and related app state are stored locally. Pinned workspace information is shared with Cavreno’s widgets on the same device. Removing a saved credential through the app removes its Keychain entry; uninstalling an app does not necessarily remove every Keychain entry.
Optional notifications
If you enable background notifications, Cavreno’s notification service processes a device identifier, Apple push token, host and workspace routing identifiers, access credentials, and notification events to register your device and deliver alerts through Apple Push Notification service.
Conversation titles and message previews are off by default and can be enabled per host. When enabled, that content is available to Cavreno’s service and Apple, and may be displayed on your lock screen. Full conversations, files, commands, and approval responses remain on the SSH connection. Notification permissions and preview settings can be changed in Cavreno and iOS Settings.
Events expire within ten minutes and are removed during queue processing. Registration proofs expire after five minutes. Unverified registrations are cleaned up during enrollment processing. Verified device records remain until access is revoked or the registration is replaced. Use Cavreno’s notification controls to revoke access; disabling alerts only in iOS Settings does not itself delete a server registration.
Voice input
Voice input uses your microphone and Apple’s Speech framework when you request it. On-device-only recognition is enabled by default. If you turn it off, audio may be processed by Apple’s speech service. You can review and edit the transcript before sending it to your remote terminal. Microphone and speech permissions can be withdrawn in iOS Settings.
Web pages and external services
Pages opened in the workspace browser can use cookies and other browser storage. GitHub, coding-agent providers, and other services you choose may process the requests and content you send to them under their own privacy policies. Cavreno does not include a coding-provider account or subscription.
Apple supports app distribution, push delivery, and speech features. Cloudflare supports delivery and security of Cavreno’s public website and notification endpoint. Google processes support email sent to the Gmail address above. These providers may process data outside your country; their privacy notices describe their practices and international-transfer safeguards.
Website, security, and support
Connecting to the website or notification endpoint exposes connection information, such as your IP address and request details, to the infrastructure serving the request. Security controls use this information to limit abuse and keep the service available. Connection and security records are retained as needed to operate the service, investigate incidents, and meet applicable obligations; infrastructure providers apply their own retention practices.
If you email support, your address, message, and attachments are used to respond and resolve the issue. Correspondence is kept while handling the request and related follow-ups or disputes. Include only the information needed to explain the problem, and exclude passwords, private keys, and private project content. You can request deletion using the contact address above.
Cavreno does not sell personal data or use it for advertising or cross-app tracking. Personal data is shared with service providers as needed for the functions described here, or when required by law.
Purposes and your rights
Data is processed to provide the features you request, answer support requests, and protect the service. Where applicable, this relies on providing the requested service, legitimate interests in support and security, consent for optional processing where required, or legal obligations.
You may request access, correction, deletion, restriction, or a portable copy of your personal data, and object to processing where applicable. You can withdraw consent for optional processing without affecting its earlier lawfulness. Contact [email protected]; information may be needed to verify that a request concerns your data. You may also complain to your data-protection authority, including the CNIL in France.
Changes to these practices will be reflected on this page and in the App Store privacy information where relevant.